Malware

Malware.AI.3955241119 (file analysis)

Malware Removal

The Malware.AI.3955241119 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3955241119 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Malware.AI.3955241119?


File Info:

name: EDF76EEB5B1BBFC68653.mlw
path: /opt/CAPEv2/storage/binaries/d98711a1d98ba62416ac8df71cdbc375b7160fefe2d7a5d914410b2c0d2c5200
crc32: B81B8188
md5: edf76eeb5b1bbfc686538b6ce9882b1b
sha1: 1accda1bb13cb9185b76c8808d132037bda6aa24
sha256: d98711a1d98ba62416ac8df71cdbc375b7160fefe2d7a5d914410b2c0d2c5200
sha512: 355875003d24cca7bb46fe637239dce71ec01e4d346fff733203db353bef464de3e901eed48dc753d99bbb5f1e3248737808990fd007be3b2b5258b7670dee01
ssdeep: 49152:lTMe5z2vrb/TXvO90dL3BmAFd4A64nsfJWL1gcNab1MHoUiSDiQL3HZWmFvUgTwJ:VMU236cugy
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T14ED59D47BC804DF9C0AEC230896692917B30B858273167E76E51F6FA2F36BD81E74365
sha3_384: 6459bf27ae895f88c530b978e73ee6437cf97053b5fe6743c6139d7725aed7f6b6c27eb6b4eb5f2342ffd15e99c5f812
ep_bytes: 4883ec28488b0565512900c700000000
timestamp: 2021-12-07 08:34:31

Version Info:

FileVersion: 16.0.14326.20404
InternalName: Word
OriginalFilename: Word.exe
ProductName: Microsoft Office
ProductVersion: 16.0.14326.20404
Translation: 0x0409 0x04b0

Malware.AI.3955241119 also known as:

MicroWorld-eScanTrojan.GenericKDZ.79465
FireEyeTrojan.GenericKDZ.79465
CAT-QuickHealTrojan.Sabsik
McAfeeArtemis!EDF76EEB5B1B
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Cobalt.7b495466
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D13669
SymantecTrojan.Gen.MBT
ESET-NOD32Win64/CobaltStrike.Beacon.A
TrendMicro-HouseCallTROJ_GEN.R002C0RLA21
KasperskyTrojan.Win32.Cobalt.hnv
BitDefenderTrojan.GenericKDZ.79465
AvastWin64:Malware-gen
TencentWin32.Trojan.Cobalt.Apwp
Ad-AwareTrojan.GenericKDZ.79465
EmsisoftTrojan.GenericKDZ.79465 (B)
ZillyaTrojan.Cobalt.Win32.2046
TrendMicroTROJ_GEN.R002C0RLA21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + ATK/ScareCrow-A
IkarusTrojan.Win64.Cobaltstrike
JiangminTrojan.Cobalt.xf
AviraHEUR/AGEN.1145901
Antiy-AVLTrojan/Generic.ASMalwS.34ED2B5
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftVirTool:Win64/Kakash.gen!D
ViRobotTrojan.Win32.Z.Agent.2754736
GDataTrojan.GenericKDZ.79465
ALYacTrojan.GenericKDZ.79465
VBA32Trojan.Cobalt
MalwarebytesMalware.AI.3955241119
MAXmalware (ai score=86)
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Malware.AI.3955241119?

Malware.AI.3955241119 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment